cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 21 of 227
CVE-2020-0734P2HIGHCVSS 8.8v1803v1903+1 more2020-02-11
CVE-2020-0734 [HIGH] CVE-2020-0734: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0681.
nvd
CVE-2018-8214P3HIGHCVSS 7.0PoCv1709v18032018-06-14
CVE-2018-8214 [HIGH] CVE-2018-8214: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly mana An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.
nvd
CVE-2020-16898P2HIGHCVSS 8.8v1903v1909+1 more2020-10-16
CVE-2020-16898 [HIGH] CVE-2020-16898: <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICM A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Adverti
nvd
CVE-2018-8208P3HIGHCVSS 7.0PoCv1709v1803+1 more2018-06-14
CVE-2018-8208 [HIGH] CVE-2018-8208: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly mana An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
nvd
CVE-2018-0826P3HIGHCVSS 7.0PoCv17092018-02-15
CVE-2018-0826 [HIGH] CVE-2018-0826: Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and W Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
nvd
CVE-2018-8134P3HIGHCVSS 7.0PoCv1709v1803+1 more2018-05-09
CVE-2018-8134 [HIGH] CVE-2018-8134: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0959P3HIGHCVSS 7.0PoCv1803v19032019-06-12
CVE-2019-0959 [HIGH] CVE-2019-0959: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2018-0751P3HIGHCVSS 7.1PoCv17092018-01-04
CVE-2018-0751 [HIGH] CWE-269 CVE-2018-0751: The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability". This CVE ID is unique from CV
nvd
CVE-2026-56159P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-56159 [CRITICAL] CWE-122 CVE-2026-56159: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50447P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50447 [CRITICAL] CWE-122 CVE-2026-50447: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58594P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-58594 [CRITICAL] CWE-190 CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57089P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-57089 [CRITICAL] CWE-416 CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized at Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-0982P3HIGHCVSS 7.0PoCv1709v1803+1 more2018-06-14
CVE-2018-0982 [HIGH] CWE-732 CVE-2018-0982: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8225P3HIGHCVSS 8.1v1709v1803+1 more2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2024-49116P3HIGHCVSS 8.1fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.78762024-12-12
CVE-2024-49116 [HIGH] CWE-416 CVE-2024-49116: Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2024-30017P2HIGHCVSS 8.8fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30017 [HIGH] CWE-122 CVE-2024-30017: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-38104P2HIGHCVSS 8.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-43611P2HIGHCVSS 8.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43611 [HIGH] CWE-20 CVE-2024-43611: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49080P2HIGHCVSS 8.8fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase